Privacy Policy
Last updated September 27, 2026
We collect as little as we need to run the site, we never sell personal information, and you can ask us to delete yours at any time.
1. Scope
This Privacy Policy explains how Aperta (“we,” “us” or “our”) collects, uses and discloses personal information through the Aperta website and related features (the “Services”). “Personal information” means information that identifies, or could reasonably be linked to, a particular person.
This policy does not cover the websites of the companies we describe, or any other third-party site we link to. Their own privacy policies apply.
2. Personal information we collect
A. Information you give us
- Messages. When you use our contact form, we collect your name, email address, the topic you choose and your message.
- Corrections. When you suggest a fix to a company card, we collect your email address, the correction itself, whether you confirmed your email with the code we sent, and whether the email address belongs to the company's domain.
B. Information collected automatically
- Log data. Our hosting provider records standard technical information when you visit, such as IP address, browser type, pages requested, referring page and the date and time of each request.
- Abuse prevention. We use your IP address to enforce limits on how many requests one visitor can make. These counters expire within two days.
- Cookies. We use strictly necessary cookies to run the Services. If you allow analytics cookies, we also collect which pages you view and which features you use, along with device and browser type, approximate location derived from your IP address, and a random identifier. See our Cookie Policy.
C. Information from public sources
The Services describe companies using public information, such as company websites, SEC filings and Wikipedia. That material can include the names and roles of people who lead those companies. We use it only to describe the company.
We do not ask you to create an account, and we do not knowingly collect sensitive personal information.
3. How we use personal information
- To provide, maintain and improve the Services.
- To review corrections, confirm the email address of the person who sent them, and update company cards.
- To respond to messages, including advertising, partnership and press inquiries.
- To protect the Services, including detecting and preventing spam, fraud, abuse and security incidents.
- With your consent, to understand how the Services are used through analytics.
- To comply with the law and enforce our Terms of Use.
4. How we disclose personal information
We disclose personal information only as described below.
- Service providers that operate the Services for us under contract: Vercel (hosting and logs), Upstash (database), Google Workspace (email) and, if you allow analytics cookies, PostHog (analytics).
- AI provider. An AI model provider helps write company cards from public information about each company. We do not send your messages or corrections to it.
- Content services. Microlink (screenshots), Jina (reading company websites) and Google (fonts and company icons). Microlink and Jina receive company web addresses, not your information. Your browser loads fonts and icons directly from Google, which receives your IP address.
- Legal and safety. When we believe in good faith it is required by law or needed to protect the rights, property or safety of us, our users or others.
- Business transfers. As part of a merger, acquisition, financing or sale of assets, subject to this policy.
- With your consent or at your direction.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. Retention
- Rate-limit counters: up to 2 days.
- Contact messages: until we have handled them, and no longer than 24 months.
- Corrections and confirmed email addresses: until you ask us to delete them, or we no longer need them to maintain company cards.
- Analytics data: up to 12 months.
- Server logs: as set by our hosting provider, typically days to weeks.
7. Your choices and rights
Cookies. You can accept, reject or change analytics cookies at any time through Cookie settings. We treat a Global Privacy Control signal from your browser as a request to opt out.
United States. Depending on where you live, including California, Colorado, Connecticut, Virginia and other states with privacy laws, you may have the right to know what personal information we hold about you, to get a copy of it, to correct or delete it, and to opt out of its sale or use for targeted advertising (we do neither). You may use an authorized agent, and you may appeal if we decline your request. We will not treat you differently for exercising these rights.
How to make a request. Contact us at privacy@askaperta.com. We may need to confirm your identity, usually by emailing the address the request is about. We respond within the time the law requires.
8. European Economic Area and United Kingdom
If you are in the EEA or the UK, we rely on these legal bases:
- Consent for analytics cookies. You can withdraw it at any time.
- Legitimate interests for running and securing the Services, preventing abuse, reviewing corrections and replying to messages.
- Legal obligation where we must keep or disclose information by law.
You have the right to access, correct, delete, restrict or object to the processing of your personal information, to receive it in a portable format, and to complain to your local data protection authority.
9. International transfers
We are based in the United States, and our service providers process information in the United States and other countries. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, for transfers out of the EEA and UK.
10. Security
We use reasonable safeguards to protect personal information, including encryption in transit, restricted access and hashed, short-lived confirmation codes. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. Children
The Services are not directed to children under 13, or under 16 in the EEA and UK, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
12. Third-party websites
Company cards link to company websites, SEC filings and other sources. We are not responsible for the content or privacy practices of those sites.
13. Changes to this policy
We may update this policy from time to time. We will change the date at the top and, for material changes, give notice on the Services before they take effect.
14. Contact us
Questions or requests about this policy can be sent to Aperta at privacy@askaperta.com.